Skip to content

2023-09-12 (disclosed) · US · MGM Resorts International

MGM Resorts cyberattack after a reported help desk call, 2023

Disclosed by the affected organisation.

In September 2023 MGM Resorts shut down systems after a cyberattack, disrupting some of its properties. MGM later estimated a negative impact of about $100 million to Adjusted Property EBITDAR and said the attackers obtained personal information of some customers who transacted before March 2019. MGM did not say how the attackers got in; the Scattered Spider group claimed responsibility and, as TechCrunch reported, told vx-underground it found an employee on LinkedIn and called the help desk to access their account.

$100M (impact; MGM's estimated negative impact on Adjusted Property EBITDAR in September 2023, per its 5 October 2023 Form 8-K. One-time expenses of less than $10 million are reported separately and not included in this value.)

Timeline

  1. 2023-09-12 MGM issues a statement that it identified a cybersecurity issue affecting certain systems and is taking steps including shutting down certain systems.
  2. 2023-09-14 A Scattered Spider representative tells TechCrunch the group was behind the attack.
  3. 2023-10-05 MGM files an 8-K estimating about $100 million of impact to Adjusted Property EBITDAR and confirming customer personal data was obtained.

Lessons

Scam types: Help desk password and MFA reset impersonation, Data theft extortion · Techniques: Voice phishing (vishing)

Sources

  1. MGM Resorts International: Statement on cybersecurity issue (8-K Exhibit 99.1, 12 September 2023) (Company disclosure, primary, accessed 2026-09-24)
  2. MGM Resorts International: Form 8-K (5 October 2023) (Company disclosure, primary, accessed 2026-09-24)
  3. TechCrunch: Hackers claim MGM cyberattack as outage drags into fourth day (News report, secondary, accessed 2026-09-24)